设备运行中发现主控cpu利用率很高
dis cpu
Chassis 1 Slot 1 CPU 0 CPU usage:
9% in last 5 seconds
9% in last 1 minute
9% in last 5 minutes
Chassis 1 Slot 3 CPU 0 CPU usage:
24% in last 5 seconds
27% in last 1 minute
29% in last 5 minutes
Chassis 1 Slot 6 CPU 0 CPU usage:
100% in last 5 seconds
99% in last 1 minute
99% in last 5 minutes
monitor thread dumbtty c 1 s 6
365 processes; 496 threads
Thread states: 18 running, 478 sleeping, 0 stopped, 0 zombie
CPU0 states: 0.00% idle, 42.71% user, 45.72% kernel, 11.55% interrupt
CPU1 states: 60.20% idle, 31.43% user, 5.35% kernel, 3.01% interrupt
CPU2 states: 99.83% idle, 0.16% user, 0.00% kernel, 0.00% interrupt
CPU3 states: 100.00% idle, 0.00% user, 0.00% kernel, 0.00% interrupt
CPU4 states: 94.13% idle, 0.00% user, 2.51% kernel, 3.35% interrupt
CPU5 states: 0.00% idle, 0.00% user, 100.00% kernel, 0.00% interrupt
CPU6 states: 100.00% idle, 0.00% user, 0.00% kernel, 0.00% interrupt
CPU7 states: 98.82% idle, 0.16% user, 0.16% kernel, 0.83% interrupt
CPU8 states: 100.00% idle, 0.00% user, 0.00% kernel, 0.00% interrupt
CPU9 states: 97.15% idle, 1.50% user, 0.67% kernel, 0.67% interrupt
CPU10 states: 99.83% idle, 0.00% user, 0.16% kernel, 0.00% interrupt
CPU11 states: 97.65% idle, 0.83% user, 0.33% kernel, 1.17% interrupt
CPU12 states: 90.95% idle, 3.68% user, 2.01% kernel, 3.35% interrupt
CPU13 states: 98.82% idle, 0.00% user, 1.00% kernel, 0.16% interrupt
CPU14 states: 0.00% idle, 0.00% user, 100.00% kernel, 0.00% interrupt
CPU15 states: 0.00% idle, 0.00% user, 100.00% kernel, 0.00% interrupt
Memory: 7958M total, 5895M available, page size 4K
JID TID LAST_CPU PRI State HH:MM:SS MAX CPU Name
310 310 5 100 R 1589h 14 6.67% [BFDP]
311 311 14 100 R 1589h 5 6.67% [BFDRX1]
312 312 15 100 R 1589h 2 6.47% [BFDRX2]
38111563811156 1 120 R 00:00:02 1 2.48% gzip
1 1 0 120 R 02:16:47 69 0.54% scmd
447 447 12 120 S 265h 10 0.40% portald
200 200 4 100 D 49:48:16 13 0.36% [RECV]
428 428 0 115 S 50:48:59 6 0.33% [karp/1]
254 254 4 102 S 77:32:03 8 0.29% [IUCT]
209 209 0 115 S 21:48:14 9 0.27% [DVP]
225 225 0 116 D 32:33:55 3 0.24% [bLK0]
301 301 4 119 S 56:25:49 10 0.24% [IbcCntRcd]
387 387 0 120 R 09:20:32 3 0.24% aaad
283 283 0 100 S 22:47:25 4 0.18% [STM_Main]
3223811171 1 120 R 00:00:00 1 0.18% diagd
319 319 11 100 S 17:18:30 5 0.15% dbmd
443 443 0 115 S 27:31:58 4 0.15% [kND/1]
253 253 4 115 D 25:08:28 4 0.13% [bRX_CleanUp]
324 346 1 120 S 05:48:22 1 0.13% syslogd
447 483 9 120 S 65:16:27 7 0.13% portald
38111483811160 0 120 S 00:00:00 1 0.13% sshd
38111503811161 0 120 S 00:00:00 1 0.13% sshd
38111543811163 0 120 R 00:00:00 1 0.13% sshd
38111523811158 0 120 S 00:00:00 1 0.11% sshd
38111623811162 0 120 S 00:00:00 1 0.11% sshd
38111573811167 0 120 R 00:00:00 1 0.09% sshd
38111643811164 0 120 S 00:00:00 1 0.09% sshd
38111653811165 0 120 S 00:00:00 1 0.09% sshd
38111663811166 0 120 S 00:00:00 1 0.09% sshd
4 4 0 115 S 00:26:29 3 0.06% [ksoftirqd/0]
295 295 0 105 S 05:16:14 3 0.06% [sock/1]
452 452 0 120 S 05:23:46 4 0.06% sshd
38111683811168 0 120 R 00:00:00 1 0.06% sshd
221 221 0 130 D 06:02:15 4 0.04% [L2X0]
222 222 0 130 R 12:46:32 3 0.04% [bC.0]
231 231 0 110 S 04:04:26 4 0.04% [DQIT]
252 252 0 115 D 09:50:59 4 0.04% [bRX2]
332 332 0 120 S 08:12:36 3 0.04% devd
427 537 7 125 S 11:12:04 6 0.04% dhcpd
38111393811139 0 120 S 00:00:00 1 0.04% sshd
38111393811147 0 120 S 00:00:00 1 0.04% sshd
38111463811153 0 120 S 00:00:00 1 0.04% sshd
38111593811159 0 120 S 00:00:00 1 0.04% sshd
38111593811170 0 120 R 00:00:00 1 0.04% sshd
38111643811172 0 120 R 00:00:00 1 0.04% sshd
38111693811169 0 120 R 00:00:00 1 0.04% sshd
40 40 12 115 S 00:06:45 1 0.02% [ksoftirqd/12]
196 196 0 120 D 04:12:29 4 0.02% [TMTH]
207 207 0 115 S 02:54:32 5 0.02% [DIPC]
212 212 0 115 D 01:42:08 5 0.02% [DTIM]
255 255 4 100 S 02:05:21 3 0.02% [STKT]
258 258 0 115 S 01:13:59 3 0.02% [CLKM]
267 267 0 100 S 00:24:38 3 0.02% [DBINT]
268 268 0 100 S 05:23:02 3 0.02% [DEVD]
286 286 0 120 S 01:19:25 3 0.02% [timesyncs]
291 291 0 120 S 00:23:02 3 0.02% [kmac/1]
314 314 0 110 S 04:45:29 4 0.02% cioctld
352 352 0 125 S 00:29:46 3 0.02% [NETM]
368 368 0 120 S 04:34:36 4 0.02% vland
396 410 11 120 S 00:45:36 1 0.02% pppd
396 415 1 120 S 04:15:43 1 0.02% pppd
426 426 11 125 S 02:30:08 1 0.02% dhcpd
426 530 7 125 S 03:34:47 6 0.02% dhcpd
426 532 13 125 S 02:35:27 4 0.02% dhcpd
427 427 11 125 S 03:44:16 1 0.02% dhcpd
431 431 0 115 S 07:48:59 3 0.02% [kfib/1]
435 435 0 120 S 01:41:20 2 0.02% lldpd
440 522 11 120 S 04:46:50 1 0.02% ospfd
440 523 11 120 S 04:31:14 1 0.02% ospfd
445 513 10 120 S 05:06:59 1 0.02% ospfv3d
446 489 11 120 S 04:58:08 1 0.02% pimd
447 472 9 120 S 08:10:20 5 0.02% portald
37966553796663 0 120 S 00:00:01 1 0.02% login
38111103811110 0 120 R 00:00:00 1 0.02% top
38111403811149 0 120 S 00:00:00 1 0.02% sshd
38111433811151 0 120 S 00:00:00 1 0.02% sshd
38111573811157 0 120 S 00:00:00 1 0.02% sshd
38111733811173 0 120 R 00:00:00 1 0.02% sshd
可以看到cpu0为0%idle,cpu0中主要就是ssh进程占用,ssh共占用1.45%,1.45%*16=23.2%,看出ssh占用了很多cpu,从日志中发现,有大量ssh登陆失败的信息,通过对这些攻击源做过滤后解决。
%Nov 8 09:15:53:803 2017 HeXin-SR8812-x SSHS/6/SSHS_LOG: -MDC=1; Authentication
failed for Bjarne from 124.117.241.152 port 32221 because of invalid username o
r wrong password .
%Nov 8 09:15:53:820 2017 HeXin-SR8812-x SSHS/6/SSHS_LOG: -MDC=1; Authentication
failed for mathml from 124.117.241.152 port 32105 because of invalid username o
r wrong password .
%Nov 8 09:15:53:910 2017 HeXin-SR8812-x SSHS/6/SSHS_LOG: -MDC=1; Authentication
failed for invalid user nicky from 211.174.123.137 port 46331 because of invali
d username or wrong password .
%Nov 8 09:15:53:940 2017 HeXin-SR8812-x SSHS/6/SSHS_LOG: -MDC=1; Authentication
failed for invalid user nemcogcc from 211.174.123.137 port 48835 because of inv
alid username or wrong password .
设备受到ssh攻击,配置acl过滤掉攻击源后cpu恢复正常。
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作